Subdomains hunting
Tips and tricks
Do not forget to perform recursive DNS enumeration.
Create a list of enumerated subdomains and the associated IP address.
Format: <subdomain><IP>
Create a list of only IP address from a subdomain list
Format: <IP>
aiodnsbrute
Very fast tool for DNS Enumeration.
crt.sh
Search for certificates associated with a domain
This one liner extract all unique common names from certificates associated to a domain.
Amass
Requires a configuration file with API keys. I really love this tool to perform subdomain enumeration.
Omnisint
Rapid7's Project Sonar dataset.
Perform amongst others things, subdomain enumeration and reverse DNS lookups.
Crobat is its CLI utility.
Censys
We can use the command line to perform searches with Censys.
Creation account is needed to get API keys and a Secret.
Export your API key and Secret to your bashsrc.
Extract the IPs addresses only
Last updated